FedRAMP (Federal Risk and Authorization Management Program) Moderate authorization means a cloud service offering has been assessed against 325 NIST 800-53 security controls and granted authorization to operate by a federal agency. It is required for cloud vendors handling moderately sensitive government data.
FedRAMP Moderate is the most common authorization level for commercial SaaS products entering the federal market. The authorization process typically takes 12–18 months and requires a Third-Party Assessment Organization (3PAO) to conduct the assessment. Authorized products are listed in the FedRAMP Marketplace. TrustVendor tracks FedRAMP authorization status and expiration.
Which vendors hold FedRAMP Moderate?
Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.
Common questions about FedRAMP Moderate
Which vendors hold FedRAMP Moderate certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current FedRAMP Moderate certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does FedRAMP Moderate certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's FedRAMP Moderate report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.